CVE-2024-47220

HIGH7.5EPSS 0.11%

HTTP Request Smuggling in ruby webrick

發布日:2024/9/22修改日:2026/2/4
也稱為:GHSA-6f62-3596-g6w7CGA-26g8-c8gp-gjfh

描述

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

參考連結(9)